{"record":{"id":"5c38c5f73b01426a","repo":"Hmbown/CodeWhale","slug":"refusing-to-replace-managed-system-path-github-migration","errorCode":null,"errorMessage":"Refusing to replace managed/system path {}.\n\n{GITHUB_MIGRATION_HELP}","messagePattern":"Refusing to replace managed/system path (.+?)\\.\n\n(.+?)","errorType":"console","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/cli/src/update.rs","lineNumber":567,"sourceCode":"                identity.android_proof,\n                fresh\n            );\n        }\n    }\n    let bytes = std::fs::read(&identity.path).context(\"failed to recheck updater binary\")?;\n    if sha256_hex(&bytes) != identity.file_hash {\n        bail!(\n            \"The running executable path changed during the update; no further files were replaced. Run the intended executable again by its full path.\"\n        );\n    }\n    Ok(())\n}\n\n/// Only the running binary and copies of those exact bytes are ours to update.\n/// Command names alone do not establish ownership of an existing sibling.\nfn validate_update_target(target: &Path, identity: &UpdateExecutableIdentity) -> Result<()> {\n    if !InstallMethod::from_path(target).supports_self_update() || protected_update_path(target) {\n        bail!(\n            \"Refusing to replace managed/system path {}.\\n\\n{GITHUB_MIGRATION_HELP}\",\n            target.display()\n        );\n    }\n    let metadata = match std::fs::symlink_metadata(target) {\n        Ok(metadata) => metadata,\n        Err(error) if error.kind() == std::io::ErrorKind::NotFound && target != identity.path => {\n            return Ok(());\n        }\n        Err(error) => {\n            return Err(error)\n                .with_context(|| format!(\"failed to inspect update target {}\", target.display()));\n        }\n    };\n    if !metadata.is_file() || metadata.is_symlink() {\n        bail!(\n            \"Refusing to replace {}: the update target is not a regular file.\\n\\n{GITHUB_MIGRATION_HELP}\",\n            target.display()","sourceCodeStart":549,"sourceCodeEnd":585,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/73e0f67d83c59909b571efdfc88c4bc28c309cb1/crates/cli/src/update.rs#L549-L585","documentation":"Codewhale's self-updater refuses to overwrite a target path that belongs to a package manager or system location (checked via InstallMethod::from_path and protected_update_path). Only the running binary and byte-identical copies of it are safe to replace; command names alone do not establish ownership of a sibling file. The message includes GITHUB_MIGRATION_HELP pointing the user at manual install/uninstall steps.","triggerScenarios":"Running `codewhale update` (run_update) where the resolved update target resolves to a path owned by a package manager (brew, apt, cargo home, etc.), or a path on the protected list; also triggered by tests where an unrelated alias, a desktop-entry primary swap, or a foreign symlink sits in the install directory.","commonSituations":"User installed via Homebrew/apt/cargo and then runs the built-in updater; a wrapper script or symlink named like the binary exists in PATH; the updater resolves a desktop launcher or alias instead of the real binary.","solutions":["Uninstall the package-manager copy (brew uninstall / apt remove / cargo uninstall) and reinstall via the official installer script so the binary is self-update-managed.","Run the updater against the real binary path, not an alias/symlink/wrapper.","Follow the GITHUB_MIGRATION_HELP printed with the error to migrate installations manually.","Check where `which -a codewhale` points and remove stale aliases in PATH."],"exampleFix":"// before: self-update over a brew-managed binary fails\n$ codewhale update\n// after: let the package manager own updates\n$ brew upgrade codewhale   # or: reinstall via official installer, then `codewhale update`","handlingStrategy":"validation","validationCode":"use codewhale_cli::update::InstallMethod;\nfn can_self_update(path: &std::path::Path) -> bool {\n    InstallMethod::from_path(path).supports_self_update()\n}\n// run before `codewhale update`; if false, update via your package manager instead","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Install codewhale only via the official installer if you want self-update to work","Never symlink or alias a package-manager-owned path as the update target","Run `which -a codewhale` to confirm which copy you are updating"],"tags":["self-update","install-method","package-manager","safety-guard"],"backgroundTag":"permission-denied","analyzedSha":"73e0f67d83c59909b571efdfc88c4bc28c309cb1","analyzedAt":"2026-09-22T01:30:00.501Z","contentChangedAt":"2026-09-22T01:30:00.501Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}